CVE-2025-42903: SAP SE SAP Financial Service Claims Management
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability.
Affected products
- SAP SE SAP Financial Service Claims Management: version 804 only; version 805 only; version 806 only; version S4CEXT 107 only; version 108 only; version 109 only
Published 2025-10-14. Last modified 2026-10-08.